漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Expat Out-of-Bounds Read via dtdCopy
Vulnerability Description
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
libexpat 缓冲区错误漏洞
Vulnerability Description
libexpat是libexpat团队开源的一款轻量级的XML解析库。 libexpat 2.8.3及之前版本存在缓冲区错误漏洞,该漏洞源于处理通过XML_ExternalEntityParserCreate创建的外部实体解析器时,ELEMENT_TYPE成员结构大小不匹配导致storeAtts越界读取attIndex成员,可能导致非CDATA属性空白规范化失败或野指针解引用导致段错误。
CVSS Information
N/A
Vulnerability Type
N/A